CLAIMS 

What is claimed is: 

1 . A system for tracking network session information, the system 
comprising: 

an information source module having a source information input and a 
standardized information output, a source information corresponds to 
network usage information, a standardized information corresponds to the 
network usage information transformed into a standard format; 

a first program having at least a first standardized information input and an 
enhanced data output, a first standardized information input corresponding 
to the standardized information, an enhanced data corresponding to the 
standardized data after at least a partial transformation, the at least partial 
transformation being defined according to a data record format; 

a second program having at least a first enhanced data input and a data record 
output, the first enhanced data corresponding to the enhanced data, a data 
record corresponding to the first enhanced data, the data record being 
formatted according to the data record format; 

a database storing the data record; and 

wherein the second program merges duplicate data records that represent the 
same network usage information. 

2. The system of claim 1 wherein the at least partial transformation is 
defined from a data enhancement procedure, and wherein the data record format 
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includes a.piurality of fields and wherein the data enhancement procedure defines how 
the standardized information is to be transformed into the plurality of fields of the data 
record format. 

3. The system of claim 2 wherein the data enhancement procedure 
includes at least a field enhancement wherein the field enhancement defines a source 
for a predetermined field in the plurality of fields. 

4. The system of claim 2 wherein the data enhancement procedure 
includes at least a field enhancement wherein *the field enhancement defines a function 
to be applied to at least a portion of the standardized data. 

5. The system of claim 2 wherein the data enhancement procedure defines 
a plurality of field enhancements, wherein each field enhancement defines network 
usage information to be stored in the plurality of fields. 

6. The system of claim 2 further comprising a second information source 
module, the second information source module having a second source information 
input and a second standardized information output, a second source information 
corresponds to a second network information, a second standardized information 
corresponds to the second network information transformed into a standard format, 
and wherein the data enhancement procedure includes a first definition of at least a 
first field in the plurality of fields being from the standardized information, and at 
least a second definition of a second field in the plurality of fields being from the 
second standardized information. 

7. The system of 6 further comprising a proxy server and a domain name 
system (DNS) server, and wherein the information source module receives the 
network usage information from the proxy server, and wherein the second information 
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source module receives the second network information from the DNS server, and 
wherein the first definition defines that a source IP address supplied by the proxy 
server should be put into the first field, and wherein the second definition defines a 
URL supplied by the DNS server should be put into the second field. 

8. The system of claim 1 wherein the second program manages the first 
program and the information source module. 

9. The system of claim 1 wherein the second program causes the data 
record to be stored in the database. 

10. The system of claim 1 wherein the information source module is 
configured to receive the network usage information from a predetermined network 
device. 

1 1 . The system of claim 1 wherein the at least partial transformation 
includes policy-based data aggregation which defines how network usage data should 
be aggregated. 

12. The system of claim 1 wherein the network usage information includes 
IP session data. 

13. The system of claim 1 wherein the data format includes a plurality of 
fields including a source IP field, a destination IP field, a source host field, a 
destination host field, a service type field, a date and time field, a duration field, a 
total number of bytes field, and a counter field. 

14. The system of claim 1 further comprising a customer care and billing 
system coupled to the database, the customer care and billing system for accessing the 
database to generate a bill from the data record. 

15. A network usage accounting system comprising: 
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an information source module coupled to receive network information from a 
network device; 

a gatherer coupled to receive the network information source module, the 
gatherer for performing data enhancements on the network information to 
create a plurality of data records; 
a central database storing the plurality of data records; and 
a central event manager coupled to receive the plurality of data records, the 
central event manager merging duplicate records in the plurality of data 
records, the duplicate records representing the same network usage 
information. 

16. The system of claim 15 wherein the information source module is 
configured to receive network information from a network device chosen from the 
group of network devices consisting of a proxy server, a domain name service server, 
a firewall, a RADIUS server, and a router. 

17. The system of claim 15 wherein the gatherer performs filtering and 
aggregation on the network information. 

18. The system of claim 15 wherein the plurality of data records have a 
predefined data format comprising a plurality of fields, and wherein the data 
enhancements includes at least a first data field enhancement to enhance the network 
information to fill in the first data field. 

19. The system of claim 18 wherein the first data field corresponds to a 
source IP address field and wherein the data enhancement includes extracting a source 
IP address value from the network information. 



C\NHi>ORTBL\MUbl\kM973314 1 (50482) 



37 



Attorney Docket Number 19623-703 



20. - - The system of claim 18 wherein the first data field corresponds to a 
URL name field and wherein the data enhancement includes requesting a URL name 
from a domain name service server. 

21. A method of gathering and aggregating network usage information 
from a set of network devices, the system using at least a first program and a second 
program coupled in communications, the method comprising: 

accessing network communications usage information; 

filtering and aggregating the network communications usage information 
using the first program; 

completing a plurality of data records from the filtered and aggregated network 
communications usage information, the plurality of data records 
corresponding to network usage by a plurality of users; 

storing the plurality of data records; and 

merging duplicate records in the plurality of data records. 

22. The method of claim 2 1 wherein completing the plurality of records 
includes accessing user account information. 

23 . The method of claim 2 1 wherein completing the plurality of records 
includes for each data record determining a corresponding source IP address, a 
corresponding URL, a corresponding type of service used, and a corresponding 
amount of time used. 

24. The method of claim 21 wherein the system includes a third program 
coupled in communications with at least the second program and wherein completing 
the plurality of records includes accessing the third program to determine network 
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account information and including the network account information in at least a first 
record in the plurality of records. 

25. The method of claim 21 wherein merging the duplicate records 
includes comparing a plurality of fields in the data records to identify data records 
corresponding to the same network session and merging the corresponding records. 

26. The method of claim 21 wherein merging the duplicate records 
includes automatically deleting a duplicate record. 

27. The method of claim 21 further comprising using the second program 
to automatically update the filtering and aggregation performed by the first program. 

28. A network usage tracking system comprising: 

means for accessing network communications usage information; 

means for filtering and aggregating the network communications usage 
information using the first program; 

means for completing a plurality of data records from the filtered and 

aggregated network communications usage information, the plurality of 
data records corresponding to network usage by a plurality of users; 

means for storing the plurality of data records; and 

means for merging duplicate records in the plurality of data records. 

29. The network usage tracking system of claim 29 wherein the means for 
completing the plurality of data records includes one or more networked computers 
running one or more programs. 

30. The network usage tracking system of claim 29 wherein the means for 
storing the plurality of data records includes a relational database. 
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3 1-.- - The network usage tracking system of claim 29 wherein the means for 
storing the plurality of data records includes an object database. 
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